GHSA-rvmm-v933-jgxq
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Quick fix
GHSA-rvmm-v933-jgxq — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^4.18.1Details
`ChartsController::actionGetNewUsersData()` at `/actions/charts/get-new-users-data` is missing a `requirePermission('viewUsers')` authorization check. Any authenticated control panel user, regardless of permissions beyond `accessCp`, can POST to this endpoint to receive time-series user registration counts for the entire site or for an arbitrary user group ID.
The `viewUsers` permission is consistently required throughout the control panel before exposing user-related data, but this action enforces only the base `accessCp` check inherited from the framework.
Each call returns the total count of users who joined the specified group in the requested period.
## Impact
Any control panel user with only `accessCp` permission can obtain the total number of registered users and their registration date distribution across any time window.
In installations with multiple editor roles, this allows a low-privilege control panel user to infer user group sizes and registration trends that would normally require the `viewUsers` permission to access.
No user PII (name, email, password) is disclosed; only aggregate counts and timestamps are returned. Confidentiality impact is low. No integrity or availability impact.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.0.0-RC1Fixed in: 4.18.1composer require craftcms/cms:^4.18.15.0.0-RC1Fixed in: 5.10.3composer require craftcms/cms:^5.10.3References
- https://github.com/craftcms/cms/security/advisories/GHSA-rvmm-v933-jgxq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-14794[ADVISORY]
- https://github.com/craftcms/cms/commit/9ee53efc1314e6aba32771c66a13e072a246f4ce[WEB]
- https://github.com/craftcms/cms[PACKAGE]
- https://github.com/craftcms/cms/releases/tag/4.18.1[WEB]
- https://github.com/craftcms/cms/releases/tag/5.10.3[WEB]
- https://vuldb.com/cve/CVE-2026-14794[WEB]
- https://vuldb.com/submit/850793[WEB]
- https://vuldb.com/vuln/376388[WEB]